Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
ID: 5e7ac006-73c2-5521-b4e3-9fb561e17cd8
STIX ID: report--5e7ac006-73c2-5521-b4e3-9fb561e17cd8
Feed Name: CosmicBytez Labs
Security researcher Yuhang Wu published a working PoC for a chained memory-corruption RCE in the Oj Ruby JSON parser used by GitLab's Jupyter notebook diff renderer, enabling authenticated attackers to achieve code execution as the `git` user on Puma web workers. The chain involves a write primitive (CVE-2026-54502) and a read/ASLR-defeat primitive (CVE-2026-54896) across Oj versions 3.13.0–3.17.1, affects GitLab CE/EE versions (notably 15.2.0–18.11.4), and has had public fixes and mitigation guidance published; self-managed instances must patch or disable the notebook diff feature to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
